Skip to content
Tidebreak Advisory

The Founder's Perspective

The documentation layer that proves the work was done

Originally posted on LinkedIn. Mirrored here so it reads on its own.

Every IT operation has three layers of documentation and most of them only take the top one seriously.

Layer one is the documentation the vendors require. Configuration guides, runbooks, incident templates. These exist because they had to.

Layer two is the documentation the team uses. Tribal knowledge written down. Scripts the senior engineer wrote for a reason the senior engineer remembers. Post-it notes and OneNote pages. These exist because someone got tired of retyping.

Layer three is the documentation that proves the work was done. Signed access reviews. Dated patch logs. Evidence registers. This is the layer that matters in an assessment, and it is the layer that most commonly does not exist.

The gap between layers two and three is the gap between "we do the work" and "we can show the work." A firm cannot forward layer two to its cyber insurance underwriter. An underwriter, or an auditor, or a regulator, will accept layer three.

#ITGovernance